7.5
CVE-2019-9637
- EPSS 7.35%
- Veröffentlicht 09.03.2019 00:29:00
- Zuletzt bearbeitet 21.11.2024 04:52:01
- Erkennungen
An issue was discovered in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. Due to the way rename() across filesystems is implemented, it is possible that file being renamed is briefly available with wrong permissions while the rename is ongoing, thus enabling unauthorized users to access the data.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 18.10
Netapp ≫ Storage Automation Store Version -
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 7.35% | 0.936 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
https://access.redhat.com/errata/RHSA-2019:2519
https://access.redhat.com/errata/RHSA-2019:3299
https://www.tenable.com/security/tns-2019-07
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00041.html
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00044.html
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00104.html
https://lists.debian.org/debian-lts-announce/2019/03/msg00043.html
https://usn.ubuntu.com/3922-2/
https://usn.ubuntu.com/3922-3/
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00012.html
https://bugs.php.net/bug.php?id=77630
https://security.netapp.com/advisory/ntap-20190502-0007/
https://support.f5.com/csp/article/K53825211
https://usn.ubuntu.com/3922-1/
https://www.debian.org/security/2019/dsa-4403